When the Department of War suspended CMMC phase 2, the question that immediately followed across the defense industrial base was predictable: if certification requirements are paused, does third-party validation still matter?
Two recent answers to that question are worth putting side by side, one from a prime evaluating its own supply chain, and one from an independent assessor’s read on what changed.
The question, and who answered it
Brett Cox, Principal of Boeing’s DFARS/CMMC Program Office, was asked directly whether subcontractors should still pursue independent, third-party validation of their compliance posture given the pause. Cox leads the team responsible for getting Boeing’s enterprise and its subsidiaries ready to meet their own CMMC requirements, which puts him on the receiving end of exactly this kind of decision when Boeing evaluates its supply chain.
His answer was unambiguous: “If I have somebody who has validated using a third party that they are meeting all of the requirements, then I have a level of assurance that they can protect my information as well.”
Why that answer matters beyond one opinion
Cox’s reasoning extends past a single preference. He drew a direct comparison to financial reporting, pointing out that publicly traded companies are required to have their financials independently verified, and asked why cybersecurity posture should be treated any differently. An independent third party sets a floor, in his words, a baseline level of assurance that doesn’t depend on taking a company’s word for it.
He also raised a second, more practical reason to keep pursuing independent validation now: exposure under the False Claims Act. A whistleblower complaint, whether well-founded or not, still costs a company money and time to defend against. Cox noted that having independent, third-party documentation showing conflict-free validation of compliance gives a company something concrete to point to if that kind of accusation surfaces, regardless of who raised it or why.
There’s a real-world signal behind this too. Cox mentioned that DCMA’s DIBCAC has, in some cases, deprioritized companies that already have a scheduled third-party assessment on the books, treating a scheduled assessment itself as a kind of preemptive risk signal in the company’s favor.
What changed, and what didn’t
It’s worth being precise here, since the headlines haven’t always been. A 60-day federal review is looking at the scope of CMMC, specifically who it applies to and how. The relief being weighed is narrow, aimed at small businesses and organizations that work exclusively with the Department of War. For the large majority of companies, the practical picture hasn’t changed.
What hasn’t changed is the more important part. The cybersecurity requirements written into defense contracts are still in force. Companies are still expected to protect sensitive information, meet the underlying standard (NIST 800-171), and maintain an accurate security score. A review of the certification program doesn’t remove the obligation behind it, and a company that self-reports an inaccurate score can still face real consequences.
Where this leaves most companies
That’s exactly the gap Cox’s comments speak to from the other side of the table. If the underlying obligation never moved, and a prime still wants to see independent proof that it’s being met, pausing to wait out the review mostly costs the companies that don’t actually fall into that narrow relief category.
For organizations already on a certification path, continuing keeps you out of the backlog that will likely form once the review wraps, and locks in a certification that’s valid for three years, ahead of whatever the review, and the coming update to the standard (NIST 800-171 Rev 3), may change next.
Insight Assurance remains fully authorized to conduct assessments and issue certifications, and continues to do so throughout the review period. Our role stays the same regardless of how the review resolves: independent assessment against the applicable standard, whether that’s a full certification, an independent check of an organization’s own self-assessment, or a mock assessment.
Cox made these comments as a guest on Summit 7’s That CMMC Show on YouTube, discussing the CMMC phase 2 suspension.
